Florida Confirms DMV Database Breached via Stolen Police Account
FLHSMV says attackers used a police department employee's credentials to access the DAVID driver database; extent of data exposure under investigation.

Key Takeaways
- FLHSMV confirmed a data breach of its DAVID driver database via stolen police department employee credentials.
- The breach was disclosed on September 11, 2026; the exact number of affected records is not yet specified.
- Attackers used compromised credentials to gain unauthorized access, highlighting risks of credential-based access to sensitive systems.
- FLHSMV is conducting incident response and reviewing access controls; no software patch is applicable.
- Organizations should enforce strong authentication, monitor for anomalous access, and regularly audit credential usage.
Quick answers
- What happened?
- The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) confirmed that its DAVID driver database was breached after attackers used credentials belonging to a police department employee. The incident, disclosed on September 11, 2026, involved unauthorized access to driver personal information, though the exact number of affected records has not been specified. FLHSMV is conducting an incident response and reviewing access controls.
- Which products are affected?
- DAVID database
- What should defenders do?
- Organizations should enforce multi-factor authentication, monitor for unusual access patterns, and regularly review and revoke unnecessary credentials. FLHSMV is conducting an incident response and reviewing access controls. Affected individuals should monitor for identity theft and follow guidance from FLHSMV.
The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that its DAVID driver database suffered a data breach, with attackers gaining access using credentials belonging to a police department employee. The disclosure, made on September 11, 2026, marks a significant security incident involving sensitive driver information held by the state agency.
According to the report, the breach involved unauthorized access to the DAVID system, which stores driver personal information. The attackers leveraged stolen credentials from a police department employee to enter the database. FLHSMV has not yet disclosed the specific volume of records exposed or the exact types of data compromised, but the incident raises concerns about the security of law enforcement-related access to state systems.
The agency has initiated an incident response and is reviewing access controls to prevent further unauthorized entry. No software patch has been mentioned, as the breach appears to stem from credential compromise rather than a technical vulnerability. The investigation is ongoing, and further details on the affected individuals and data are expected to be released as they become available.
This incident underscores the risks associated with credential-based access to sensitive government databases, particularly when third-party entities such as local police departments hold access privileges. Organizations relying on shared or delegated credentials should reassess their authentication and monitoring practices to mitigate similar threats.
Security Details
The breach involved unauthorized access to the FLHSMV DAVID driver database using credentials belonging to a police department employee. The exact data exposed and number of affected individuals have not been disclosed. The incident was confirmed by FLHSMV, and the method of access was clearly stated as stolen credentials. No CVE identifiers or CVSS scores are applicable as this is a credential-based breach, not a software vulnerability.
Affected products
DAVID database
Mitigation
Organizations should enforce multi-factor authentication, monitor for unusual access patterns, and regularly review and revoke unnecessary credentials. FLHSMV is conducting an incident response and reviewing access controls. Affected individuals should monitor for identity theft and follow guidance from FLHSMV.
Sources
BleepingComputer
Florida confirms DMV database breached via stolen police account
Sep 11, 2026 · 19:00
Original link
Related Security News

Times Car Confirms Data Breach Affecting 6.6 Million User Accounts
Times Car, a Japanese car-sharing service, has confirmed a data breach compromising approximately 6.6 million user accounts. The incident was disclosed late last week, with the exact attack vector and nature of exposed personal information yet to be fully specified. Authorities and the company are reportedly investigating the breach.

Bitget Reports $388M Loss Following Exploitation of Third-Party Security Product Flaw
Bitget disclosed that an attacker stole approximately $388 million by exploiting a vulnerability in a third-party security product integrated into the exchange's infrastructure. The threat actor used the flaw to obtain high-level internal credentials, which were subsequently used on September 24 to issue fraudulent withdrawal commands to Bitget's wallet system. The exchange confirmed that most user funds remain secure, though the full extent of exposure is under investigation.



